Описание
A flaw was found in OpenTelemetry Operator for Kubernetes. A tenant with permissions to create or update a ServiceMonitor resource can configure the bearerTokenFile field to point to the Collector's service account token path. This causes the Collector to send its mounted service account JSON Web Token (JWT) to an attacker-controlled scrape target. This vulnerability allows for information disclosure, potentially granting the attacker the same level of access as the OpenTelemetry Collector pod's service account within the Kubernetes API. This could lead to further enumeration and identification of targets, and potentially reading other sensitive files on the Collector pod.
Отчет
A flaw was found in the OpenTelemetry Operator for Kubernetes. The TargetAllocator preserves the ServiceMonitor bearerTokenFile field through to the Collector's Prometheus scrape configuration. A tenant who can create or update a ServiceMonitor can set bearerTokenFile to the Collector's mounted service account token path, causing the Collector to send its JWT to an attacker-controlled scrape target on every scrape interval. Red Hat OpenShift distributed tracing 3.10 ships a fixed version of the operator (>= 0.152.0) and is not affected.
Меры по смягчению последствий
Upgrade to opentelemetry-operator 0.152.0 or later, which adds DenyFSAccessThroughSMs support to drop ServiceMonitor and PodMonitor endpoints that reference arbitrary files on the file system.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat OpenShift distributed tracing 3 | opentelemetry-operator | Not affected |
Показывать по
Дополнительная информация
Статус:
7.7 High
CVSS3
Связанные уязвимости
OpenTelemetry Operator for Kubernetes's ServiceMonitor bearerTokenFile reads arbitrary local file and sends contents as bearer auth
7.7 High
CVSS3